Lifecycle-Based VEX Risk Dataset for Software Supply Chain Governance
收藏资源简介:
This dataset provides structured risk metadata derived from lifecycle-based analysis of Vulnerability Exploitability eXchange (VEX) statements. It is designed to support governance, auditing, and research use cases where exploitability assertions must be evaluated over time rather than treated as static status indicators. The dataset includes attributes such as lifecycle phase, scope, validity context, exploitability conditions, and risk interpretation categories intended to reflect real-world VEX usage challenges observed in enterprise and open-source software supply chains. It can be used by software producers, consumers, auditors, and tool vendors to study VEX staleness, context drift, governance controls, and integration patterns with SBOM and compliance workflows.



